VYPR
High severity7.5NVD Advisory· Published Jun 11, 2020· Updated Jun 17, 2026

CVE-2020-13170

CVE-2020-13170

Description

HashiCorp Consul and Consul Enterprise did not appropriately enforce scope for local tokens issued by a primary data center, where replication to a secondary data center was not enabled. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/hashicorp/consulGo
>= 1.6.0-beta1, < 1.6.61.6.6
github.com/hashicorp/consulGo
>= 1.7.0, < 1.7.41.7.4

Affected products

5
  • HashiCorp/Consuldescription
  • ghsa-coords2 versions
    >= 1.6.0-beta1, < 1.6.6+ 1 more
    • (no CPE)range: >= 1.6.0-beta1, < 1.6.6
    • (no CPE)range: >= 1.4.0, < 1.6.6
  • Hashicorp/Consul2 versions
    cpe:2.3:a:hashicorp:consul:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:hashicorp:consul:*:*:*:*:*:*:*:*range: >=1.4.0,<1.6.6
    • cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*range: >=1.4.0,<1.6.6

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.